1. Network Anomaly Detection Using One Class Support Vector Machine.
- Author
-
Rui Zhang, Shaoyan Zhang, Yang Lan, and Jianmin Jiang
- Subjects
ANOMALY detection (Computer security) ,SUPPORT vector machines ,ALGORITHMS ,COMPUTER networks ,TELECOMMUNICATION - Abstract
Anomaly detection is automatic identification of the abnormal behaviors embedded in a large amount of normal data. This paper presents a method based on one class support vector machine (OCSVM) for detecting network anomalies. The telecommunication network performance data are used for the investigation. Firstly, the raw data are preprocessed in order to produce the vector sets required by the OCSVM algorithm. After preprocessing, the vector set of the training data is used to train the OCSVM detector, which is capable of learning the nominal behaviors of the data. The trained detector is then applied on the test data to detect the anomalies. The detected anomalies are finally categorized into major or minor level by comparing with a threshold. In this paper, experiments on three different types of performance data are presented and the results demonstrate the promising performance of the algorithm. [ABSTRACT FROM AUTHOR]
- Published
- 2008